CVE-2017-17552: CSRF
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17552?
CVE-2017-17552 is a vulnerability in Zoho ManageEngine AD Manager Plus build 6590 - 6613 that allows attackers to conduct URL Redirection attacks.
How does CVE-2017-17552 work?
CVE-2017-17552 works by allowing attackers to bypass CSRF protection or masquerade a malicious URL as trusted using the src parameter in the /LoadFrame function of Zoho ManageEngine AD Manager Plus.
What is the severity level of CVE-2017-17552?
The severity level of CVE-2017-17552 is high, with a severity value of 8.8.
What software versions are affected by CVE-2017-17552?
Versions 6590 - 6613 of Zoho ManageEngine AD Manager Plus are affected by CVE-2017-17552.
How can I mitigate the CVE-2017-17552 vulnerability?
To mitigate the CVE-2017-17552 vulnerability, it is recommended to update to a version of Zoho ManageEngine AD Manager Plus that is not affected by the vulnerability.